THREATOPS
THREAT OPSThreat News › CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests

CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests

medoss_secPublished 2026-08-03

<p>Posted by David Handermann on Aug 03</p>Severity: High <br /> <br /> Affected versions:<br /> <br /> - Apache NiFi (org.apache.nifi:nifi-web-api) 1.5.0 through 2.10.0<br /> <br /> Description:<br /> <br /> Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey <br /> encoding filter. The framework enforced a configurable maximum request s

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/399